MailGuard 27 October 2022 12:55:30 AEDT 6 MIN READ

New email scam warns your SendGrid account will be removed

MailGuard is now blocking a scam email which claims that the recipient’s payment to SendGrid, Twilio’s email marketing campaign platform, was unsuccessful, but is actually an attempt to steal their account credentials.  

As the scam is so well designed, it's important that users proceed with caution when receiving any emails similar to the one shown below. If an attacker is able to obtain your SendGrid login information, they have access to your business’s entire marketing contact list, putting your customers at risk of being scammed as well.  

The sender name of the email shows “TwilioSendGrid”, but the sender’s email address is “info(at)smile-kids-hoikuen(dot)jp”, which originates from a domain and server that are associated with a Japanese web hosting company and is unrelated to SendGrid.  

The subject line reads “Suspention Notice”, and the email begins with a header that states “Your payment to SendGrid was unsuccessful.” In the greeting, the recipient’s username in their email address is auto-filled in an effort to make it more personalised, and they’re then informed that because of their unsuccessful payment, their account is scheduled for removal and are instructed to click a button to “Fix now”.   

Despite a couple of spelling errors, the email is incredibly well crafted. SendGrid’s branding is used heavily, including their copyright information, head office address, and links to their social media pages, and formatted in a way that makes it appear as though this could be legitimate correspondence from the company.   

Here’s an example of the email:  

image 1-3

When the user clicks the button in the email, they’re taken to a phishing site which is an almost identical replica of the SendGrid login page and asked to enter their account’s username and password. image 2-Oct-27-2022-01-54-13-6777-AM

And, after entering these details, they’re shown an error message which states “Your username or password is invalid”. At this point, the victim’s credentials are harvested for later use, and the scam does not proceed further.  

image 3-4

 

 

MailGuard advises all recipients of this email to delete it immediately without clicking on any links, and if you’re still unsure of the legitimacy of the email, we recommend that you log in to your SendGrid account in a different browser and check your billing information there. Providing your personal details can result in your sensitive information being used for criminal activity and may have a severe negative impact on your business and its’ financial well-being.  

MailGuard urges users not to click links or open attachments within emails that:       

  • Are not addressed to you by name.       
  • Appear to be from a legitimate company but use poor English or omits personal details that a legitimate sender would include.       
  • Are from businesses that you were not expecting to hear from, and/or       
  • Take you to a landing page or website that is not the legitimate URL of the company the email is purporting to be sent from.      

Many businesses turn to MailGuard after an incident or a near miss, often as a result of an email similar to the one shown above. If unwanted emails are a problem for your business, don’t wait until it’s too late.  

Reach out to our team for a confidential discussion by emailing expert@mailguard.com.au or calling 1300 30 44 30.

One email is all that it takes     

All that it takes to devastate your business is a cleverly worded email message that can steal sensitive user credentials or disrupt your business operations. If scammers can trick one person in your company into clicking on a malicious link or attachment, they can gain access to your data or inflict damage on your business.     

For a few dollars per staff member per month, you can protect your business with MailGuard's predictive and advanced email security. Talk to a solution consultant at MailGuard today about securing your company's inboxes.  

Stay up-to-date with MailGuard's latest blog posts by subscribing to free updates. Subscribe to weekly updates by clicking on the button below.  

Keep Informed with Weekly Updates